# CVE-2025-12107

## Summary

- **CVE ID:** CVE-2025-12107
- **Severity:** HIGH
- **CVSS Score:** 8.4 (CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-1336, CWE-77, CWE-94
- **Published:** Feb 19, 2026
- **Last Modified:** Sep 3, 2026

## Description

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates. 

 Successful exploitation of this vulnerability could allow a malicious actor with admin privilege to inject and execute arbitrary template code on the server, potentially leading to remote code execution, data manipulation, or unauthorized access to sensitive information.

## Affected Products

- WSO2 — WSO2 Identity Server (5.11.0.130)
- WSO2 — Identity Server (0)
- WSO2 — Identity Server (5.11.0)
- WSO2 — Identity Server (6.0.0)
- WSO2 — Identity Server (6.1.0)

## References

- [CNA](https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4517/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.62%
- **EPSS Percentile:** 48.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._